News
When AI is trained for treachery, it becomes the perfect agent
Opinion Last year, The Register reported on AI sleeper agents. A major academic study explored how to train an LLM to hide destructive behavior from its users, and how to find it before it triggered. The answers were unambiguously asymmetric — the first is easy, the second very difficult. Not what anyone wanted to hear.…
Trump demands Microsoft fire its head of global affairs
US President Donald Trump has demanded Microsoft fire its recently appointed head of global affairs Lisa Monaco.…
Dutch teen duo arrested over alleged 'Wi-Fi sniffing' for Russia
Infosec In Brief Police in the Netherlands arrested two 17-year-olds last week over claims that Russian intelligence recruited them to spy on the headquarters of European law enforcement agencies.…
Datacenter fire takes 647 South Korean government services offline
Asia In Brief Over 600 e-government services operated by South Korea’s government are offline after a datacenter fire disrupted operations.…
Hunt for RedNovember: Beijing hacked critical orgs in year-long snooping campaign
RedNovember, a Chinese state-sponsored cyberspy group, targeted government and critical private-sector networks around the globe between June 2024 and July 2025, exploiting buggy internet-facing appliances to deploy a Go-based backdoor called Pantegana and other offensive security tools, including Cobalt Strike and SparkRAT.…
Alibaba unveils $53B global AI plan – but it will need GPUs to back it up
Analysis Alibaba this week opened an AI war chest containing tens of billions of dollars, a revamped LLM lineup, and plans for AI datacenters in Europe. But it also prompted a flurry of questions over how it will achieve all this in an increasingly fragmented IT landscape, when critical resources are in short supply.…
Cyber threat-sharing law set to shut down, along with US government
Barring a last-minute deal, the US federal government would shut down on Wednesday, October 1, and the 2015 Cybersecurity Information Sharing Act would lapse at the same time, threatening what many consider a critical plank of US cybersecurity policy.…
Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
The long-running XCSSET malware strain has evolved again, with Microsoft warning of a new macOS variant that expands its bag of tricks while continuing to target developers.…
Salesforce facing multiple lawsuits after Salesloft breach
Salesforce is facing a wave of lawsuits in the wake of a cyberattack that exposed customer data.…
‘An attacker's playground:’ Crims exploit GoAnywhere perfect-10 bug
Security researchers have confirmed that threat actors have exploited the maximum-severity vulnerability affecting Fortra's GoAnywhere managed file transfer (MFT), and chastised the vendor for a lack of transparency.…
LockBit's new variant is 'most dangerous yet,' hitting Windows, Linux and VMware ESXi
Trend Micro has sounded the alarm over the new LockBit 5.0 ransomware strain, which it warns is "significantly more dangerous" than past versions due to its newfound ability to simultaneously target Windows, Linux, and VMware ESXi environments. …
Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking sales
A now-fixed flaw in Salesforce’s Agentforce could have allowed external attackers to steal sensitive customer data via prompt injection, according to security researchers who published a proof-of-concept attack on Thursday. They were aided by an expired trusted domain that they were able to buy for a measly five bucks.…
Volvo North America confirms staff data stolen following ransomware attack on IT supplier
Volvo North America is the latest large organization to announce attackers accessed employee data after a ransomware attack struck its HR system provider.…
UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild
Cybersecurity agencies on both sides of the Atlantic are sounding the alarm over Cisco firewall vulnerabilities that are being exploited by an "advanced threat actor."…
UK to roll out mandatory digital ID for right to work by 2029
The UK government plans to issue all legal residents a digital identity by the end of the current Parliament, which could run until August 2029, with its use required to get a job.…
Brits warned as illegal robo-callers with offshored call centers fined half a million
The UK's data protection watchdog fined two Brit businesses with offshore call centers £550,000 (c $735,000) over illegal automated marketing calls.…
North Korea's Lazarus Group shares its malware with IT work scammers
North Korean-linked crews connected to the pervasive IT worker scams have upped their malware game, using more advanced tools, including a backdoor that has much of the same code as Pyongyang's infamous Lazarus Group deploys.…
Callous crims break into preschool network, publish toddlers' data
A cyber criminal crew has targeted Kido International, a preschool and daycare organization, leaking sensitive details about its pupils and their parents.…
Zero-day deja vu as another Cisco IOS bug comes under attack
Cisco has confirmed a new IOS and IOS XE zero-day, the latest in a string of flaws that attackers have been quick to weaponize.…
EU starting registration of fingerprints and faces for short-stay foreigners
Travelers including Britons and Americans visiting most European countries will have to register their fingerprints and faces under a system that goes live next month.…
Pages
